
Protect the heart of your company
Security in IT is like locking your house or car –
it doesn't stop the bad guys, but if it's good enough
they may move on to an easier target.
Company Profile
insecor® is a Swiss company. Data protection, information security and ethical corporate governance - that's my area of expertise. With a trained eye for detail and the big picture, I support companies in fulfilling their responsibility towards people, data and technology. Together, we find the right balance between security, innovation and trust.
Management
- MAS Law (Licentiate)
- Certificate of Applied Generative AI for Digital Transformation, MIT Professional Education, Cambridge, USA
- CIPP/E - Certified Information Privacy Professional/Europe
- CAS Information Security
- CEO, owner of the company
Languages: German, English and French
Portfolio of services
As a legal professional and business consultant with over 20 years of experience, I support organizations in a wide range of industries with issues relating to data protection law (GDPR; DPA), information security and ethical corporate governance. My focus is on practical, sustainable advice - whether in the introduction of management systems, audits or in the role of an ombudsperson.
Thanks to a wide-ranging network and my diverse mandates, I have been able to continuously deepen my specialist knowledge and expand it to include exciting new topics - for example in dealing with artificial intelligence (AI) or in trust-based mediation between organizations and employees.
I am pleased to accompany you in your projects, e.g. in the implementation of the EU General Data Protection Regulation (GDPR) as well as the Swiss Data Protection Act (“DPA”). Investing in data protection, information security as well as in ethical corporate governance is less about keeping up with other companies but more about initiating what your organization genuinely needs. I support you with strong experience and expertise in what you need for your business.
Data Protection & information security
- Governance & risk analysis in the areas of data protection, information security, and the use of artificial intelligence (AI)
- Audits & assessments in accordance with DPA, GDPR, ISO/IEC 27000 family, and other standards (e.g., BSI, NIST)
- External data protection consulting (DPA) and mandates as data protection officers (GDPR)
- Establishment and further development of data protection management systems (DSMS)
- Development of company-wide guidelines on data protection, information security, and AI
- Planning and implementation of technical and organizational measures (TOMs) in accordance with applicable data protection laws (GDPR, DPA) and standards such as ISO/IEC 27000 series, NIST, BSI standards, etc.
- Introduction and support of information security management systems (ISMS)
- ICT project support focusing on data protection, information security, and AI
Cybersecurity & fighting cybercrime
- Risk management: consulting, risk analysis, and recommendations for measures
- Cybersecurity audits: situation analysis of the IT infrastructure with regard to cybersecurity and data protection, and more
Ethics & interpersonal relations
- Mandate as ombudswoman for companies and organizations
- Function as reporting office for boundary violations
- Coaching young people in education
Methods & standards
I greatly value interdisciplinary collaboration between executive management, lawyers, security officers, IT project managers, and software developers. In doing so, I take into account the relevant legal foundations as well as recognized standards, methods, and best practices such as the ISO/IEC 27000 series, BSI standards, and NIST.
Some highlights of my work…
- Various mandates as Data Protection Officer (DPO) according to the applicable data protection laws GDPR as well as the Swiss Data Protection Act ("DPA")
- Performing various audits, consulting, editing of legal documents and give trainings as Data Protection Officer (DPO)
- Carrying out various Privacy Impact Assessments (PIA) and recommending technical and organisational measures (TOMs)
- Authoring information security concepts (incl. protection needs analysis and risk analysis) for information systems containing sensitive data
- Mandate as the only external technical expert for data protection management systems (incl. ISO 27001 and ISO 27002) of the Swiss Accreditation Service (SAS)
Memberships
Associations and expert committees
- HIV - Handels- und Industrieverein des Kantons Bern
- IAPP - International Association of Privacy Professionals
- ISACA - Information Systems Audit and Control Association
- SF - Schweizer Forum für Kommunikationsrecht
- SK ITS - Sector Comittee Information Technology
- SPICT - Verein Swiss Police ICT
- swissICT - Schweizerischer Verband der Informations- und Kommunikationstechnologie
Alumni organizations
- Alumni IUS Frilex – Alumni der Rechtswissenschaftlichen Fakultät der Universität Freiburg
- Alumni der MIT Professional Education
- SGRP - Sicherheitsgruppe Schweiz
Contact
I look forward to hearing from you!
insecor gmbh
Länggassstrasse 8
P.O. Box
3001 Berne
Switzerland
+41 31 302 09 18
info(at)insecor.ch
www.insecor.ch